Privacy Summary

The strong, distinctive promises we make about your data.

  • Encrypted throughout
  • UK and EU only, zero AI retention
  • Pseudonymised
  • UK GDPR and DPA 2018

Your Data Stays Yours

You own your health record. The deliverables are files you keep. There is no portal, no account, no lock-in.

Never Sold, Never Shared

Your data is not sold or shared with insurers, advertisers, brokers, researchers, or anyone else. The only third parties that ever touch it are the named processors in the Privacy Notice, each under a data processing agreement. If the service is bought as a gift, the payment processor only ever handles the purchaser’s payment details, never anyone’s health data.

Deleted Within Weeks, Not Years

Your identifiable health data, including any identity documents you share for a Subject Access Request, is deleted within 28 days of delivery. Right-to-erasure requests are actioned the same session.

You Are the Customer, Not the Product

No third-party trackers, no profiling, no advertising cookies. We pay for a few adverts so people can find us, but we do not let advertising platforms follow you here: no conversion tracking, no retargeting, and no cookie banner because there is nothing to consent to. Our analytics is Cloudflare Web Analytics plus our own counters for how far down a page people read and how long they stay: cookieless, aggregate, no personal data, and nothing kept that describes an individual visit (the detail is in the Privacy Notice). The two pieces of this site that come from elsewhere, the booking calendar and the explainer videos, stay dormant until you click them, so nothing of theirs reaches your browser unless you ask for it. Your data is never used to target, profile, or market to you. You pay for the service, and that is the entire business model.

The chat in the corner of these pages is built and run by us, not bought in from a chat company, so nothing you type goes to a third party with its own view of your visit. An automated assistant answers from what is already published on this site, using a model run for us by Amazon Web Services in London on a zero-retention basis, and Tom can join the conversation himself. Conversations are deleted after 30 days, are kept apart from the reading counters above, and are never joined to them. Please keep health details, NHS numbers and dates of birth out of it: nothing in the chat needs them (the detail is in the Privacy Notice).

Access Is Kept to a Minimum

No contractors or third parties have access to your records. This eliminates the most common cause of data breaches: unnecessary access.

Identifiers Removed Before Any AI Processing

Before any data goes to an AI model, direct identifiers (name, date of birth, address, NHS number, contact details) are stripped out at two independent layers as a defence-in-depth measure.

Zero Retention by the AI Provider

Prompts and responses are not stored, logged, or used for model training by the AI provider. EU-only routing is enforced at two layers. Evidence available on request.

End-to-End Encrypted Storage, UK/EU Only

Your data is held only in encrypted storage with zero-access architecture, meaning the storage provider cannot read your files. It does not leave the UK and EU at any point.

How We Approach This

  • Conservative defaults. Encryption everywhere, identifier removal before AI, defence-in-depth, and short retention by design rather than by request.
  • Transparency. A Data Protection Impact Assessment, and evidence for zero-retention and EU-only enforcement, are available on request.
  • Honesty about limits. We can’t control how your GP sends records, or what you do with your data once you receive it. Where our control ends, we say so.

Read the Full Detail